Between the Professional Customer and iBetterCoach (qualification of the data controller / data processor roles subject to legal review — see the "[UNDER LEGAL REVIEW]" block at the top of this document)
Version: 1.2 Date: 27 July 2026
⚠️ Notice: Template prepared as a foundation. Requires review by a Portuguese lawyer specialised in GDPR before being used with real customers.
⚠️ [UNDER LEGAL REVIEW] Qualification of the data controller
This point is being determined by legal advice and may change the framing of several sections of this document. There are two possible readings of iBetterCoach's role: (a) Data processor of the Athlete's data, processed on behalf of the Professional (data controller), under the terms of this DPA; or (b) Data controller, possibly in joint controllership with the Professional (Art. 26 GDPR), given that iBetterCoach maintains a direct relationship with the Athlete (own account, acceptance of the Terms and consent provided directly to the Platform) and processes data for its own purposes (metrics/gamification, product improvement and security). The final determination will be reflected in this section, in the DPA document and in the consent flows. Pending validation by a lawyer specialised in GDPR.
Reading note. This DPA is drafted on the assumption of scenario (a) — iBetterCoach as data processor of the Professional Customer. Should the legal review adopt scenario (b), the references throughout this document treating iBetterCoach as "Processor" and the Professional Customer as sole "Controller" will have to be requalified (including legal basis, roles and consent flows).
Recitals
This Data Processing Agreement ("DPA") governs the processing of personal data carried out by iBetterCoach ("Processor") on behalf of the Professional Customer ("Controller") in the context of the use of the iBetterCoach platform (qualification of the roles subject to legal review — see the relevant section at the start of the document).
This DPA forms an integral part of the Terms of Use and applies whenever the Professional Customer, acting as a Personal Trainer, nutritionist, physical education teacher, physiotherapist or other health, sports or wellness professional, collects, stores or processes personal data of Athletes (data subjects) through the Platform.
In case of conflict between this DPA and the Terms of Use, the DPA prevails as regards the processing of personal data.
1. Definitions
The terms used in this DPA have the meaning given to them by Regulation (EU) 2016/679 (GDPR), namely:
- Personal Data: any information relating to an identified or identifiable natural person.
- Processing: any operation or set of operations performed on personal data.
- Data Controller (Controller): the natural or legal person who determines the purposes and means of processing. In this DPA, the Professional Customer.
- Data Processor (Processor): the natural or legal person who processes personal data on behalf of the Controller. In this DPA, iBetterCoach.
- Sub-processor: a third party engaged by the Processor to assist in the processing (e.g., Clerk, Supabase, Vercel).
- Data Subject: the Athlete whose personal data are processed.
- Health Data: personal data concerning the physical or mental health of the data subject, including the provision of healthcare services, qualified as a special category under Article 9 GDPR.
- Personal Data Breach: a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
2. Subject matter and duration
2.1 Subject matter
iBetterCoach processes, on behalf of the Professional Customer, personal data necessary to:
- Manage the professional relationship between the Customer and the Athletes
- Collect health anamnesis and physical assessment
- Generate training and nutrition prescriptions with the support of the algorithmic engine
- Track progress, log sessions and enable Customer-Athlete communication
- Integrate with wearables (when authorised by the Athlete)
2.2 Duration
This DPA remains in force for as long as the Professional Customer uses the Platform and terminates automatically upon account closure, without prejudice to obligations that must survive termination (return or deletion of data, confidentiality, cooperation with data subject requests).
3. Types of data and data subjects
3.1 Categories of Personal Data processed
- Identification data: name, date of birth, sex, photo, contact details
- Anthropometric data: weight, height, perimeters, body fat percentage, bioimpedance data
- Health data (special category, Art. 9 GDPR):
- Anamnesis / sensitive clinical data (conditions, medical history, medication, surgeries, allergies, injuries, medical restrictions): entered into the WEB application by the Professional Customer, not collected directly in the Athlete's mobile application.
- Wearable data synchronised automatically from Apple Health / Health Connect, with the Athlete's specific and optional health consent (see Section 3.3): steps, heart rate, resting heart rate, sleep, HRV, VO₂max and training sessions.
- Sports data: goals, training history, 1RM, loads, volumes, progression
- Nutritional data: preferences, restrictions, intolerances, food log
- Usage data: access logs, Platform interactions, prescriptions generated
3.2 Categories of Data Subjects
- Athletes registered on the Platform (minimum age of use: 16 years)
- Customer team members (interns, assistants, co-trainers) with access authorised by the Customer
⚠️ [to be confirmed by the lawyer] As this concerns Athletes aged 16-17 and health data (special category, Art. 9 GDPR), it must be confirmed whether the consent of the data subject alone is sufficient or whether the consent of the holder of parental responsibility is required.
The submission of body photos is prohibited for minors under 18 (technical block on the Platform). Manual anthropometric measurements and wearable synchronisation do not depend on uploading photos.
3.3 Consents recorded by the Athlete
Anamnesis and body photographs
Explicit consent to the processing of anamnesis health data is given by the Athlete on a dedicated page, through a single-use token link sent to the Athlete's email address or while the Athlete is authenticated. The channel is independent from the Professional Customer, who cannot consent on the Athlete's behalf or use their own device as the channel for that act.
The choices are recorded separately by type: acceptance of the Athlete Terms (TERMS), confirmation of the Privacy Policy (PRIVACY) and consent to health data processing (HEALTH_DATA) are required to use the service; authorisation for body photographs (PHOTOS) is separate and optional. Refusing photographs does not prevent use of the Platform; only photographic assessment becomes unavailable.
Each record retains the version and SHA-256 cryptographic digest of the text actually presented, the language, date and type of the choice, without the Professional Customer acting on the Athlete's behalf.
While the required choices have not been recorded, the Athlete's access to the application and to features that process their clinical data remains blocked. The request's initial period is 30 days and may be extended once for a further 30 days, with the extension recorded.
Authorisation for photographs may be given later or withdrawn at any time. Withdrawal immediately blocks new reads and new URL issuance for photographs; a bearer URL issued before withdrawal may remain functional for no more than 15 minutes.
Wearable synchronisation
The automatic synchronisation of wearable data (Section 3.1) relies on the Athlete's health consent, which is:
- Separate, specific and optional — the Platform works without it;
- Revocable at any time (Art. 7(3) GDPR);
- Required BEFORE any synchronisation, in the order: (1) legal consent in the app → (2) operating system permission → (3) synchronisation.
Two "yeses" are required: legal consent in the application and the operating system permission (Apple Health / Health Connect). The OS permission does not replace the legal consent. iBetterCoach records the version, the text and the date of the consent given.
(Qualification of the roles and of the legal basis subject to legal review — see the relevant section at the start of the document.)
3.4 Purposes of health data
The synchronised health data are processed for the following purposes:
- Reading of habits by the Professional Customer, in the follow-up of the Athlete;
- Presentation of metrics to the Athlete under a logic of responsible gamification (celebrating habits and adherence, without encouraging effort beyond the limits nor exceeding the Professional's prescription).
4. Obligations of iBetterCoach (Processor)
iBetterCoach undertakes to:
-
Process personal data only on documented instructions from the Professional Customer, except where required by law. The Terms of Use, this DPA and the Platform configurations constitute valid documented instructions.
-
Ensure that persons authorised to process the data (employees and contractors) are bound by confidentiality obligations or are under an appropriate statutory duty of confidentiality.
-
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including (without limitation):
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Pseudonymisation where applicable
- Strong authentication (Clerk) and role-based access control enforced in the application layer — per-Athlete guards and multi-tenant isolation — with administrative access logging
- Regular backups with restore tests
- Access log monitoring and anomaly detection
- Business continuity and disaster recovery plan
- GDPR and security training for the team
-
Respect the conditions for engaging sub-processors as set out in Section 5.
-
Assist the Professional Customer, insofar as possible and taking into account the nature of the processing, to:
- Respond to data subject rights requests by Athletes
- Comply with the security obligations of Articles 32 to 36 GDPR
- Conduct Data Protection Impact Assessments (DPIA)
-
Notify the Customer without undue delay and within 48 hours after becoming aware of a personal data breach affecting the Customer.
-
Upon termination of the services, and at the Customer's choice, return or delete the personal data, except for what Union or Portuguese law requires to be retained (in particular tax/accounting records — see Section 10.1).
-
Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow audits, including inspections, conducted by the Customer or by another auditor mandated by the Customer, with reasonable prior notice and no more than once per year (except in case of incident).
-
Maintain a Record of Processing Activities under Article 30(2) GDPR.
5. Sub-processors
5.1 General authorisation
The Professional Customer expressly authorises iBetterCoach to engage sub-processors for the provision of the service, namely:
| Sub-processor | Service | Data processed | Location | Safeguard |
|---|---|---|---|---|
| Supabase Inc. | PostgreSQL database and storage | Platform data, including health data and photographs when authorised | EU — Ireland (eu-west-1) | DPA + SCC |
| Clerk Inc. | Authentication, user management and organization management | Identity, email, session and organization identifiers | USA | DPA + SCC + DPF |
| Vercel Inc. | Hosting, edge functions and CDN | Technical data, including IP address, HTTP headers and access logs | EU — Dublin (dub1) | DPA + SCC + DPF |
| Resend, Inc. | Transactional service email delivery, including account deletion notices and operational notifications | Email address, name and message content | EU (eu-west-1) | DPA + SCC |
| Stripe, Inc. | Payment processing and billing | Professional Customer identity and email, billing address, VAT/tax ID and subscription data | USA (with Irish entity Stripe Payments Europe Ltd.) | DPA + SCC + DPF |
Note on the payment chain. The Customer's card data (PAN, CVV) are tokenised directly in the browser by Stripe and never reach iBetterCoach or Clerk.
The up-to-date list of iBetterCoach's sub-processors is set out in Section 7.1 of the Privacy Policy.
5.2 Notification of changes
iBetterCoach will notify the Customer at least 30 days in advance of any change to the list of sub-processors (addition, replacement, removal). The Customer may object on reasonable grounds within 14 days. If the objection is reasonable, iBetterCoach will seek an alternative; if none is feasible, the Customer may terminate the contract without penalty.
5.3 Liability
iBetterCoach remains fully liable to the Customer for compliance with GDPR obligations by sub-processors.
6. Data subject rights
iBetterCoach provides the Professional Customer with technical tools to respond to Athlete requests regarding their rights, namely:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure / right to be forgotten (Art. 17)
- Restriction of processing (Art. 18)
- Portability (Art. 20) — iBetterCoach provides the data in a structured format upon the Customer's request
- Objection (Art. 21)
- Not subject to automated decision-making (Art. 22) — the Platform ensures that no prescription takes effect without human validation by the professional
If an Athlete contacts iBetterCoach directly, iBetterCoach will forward the request to the Professional Customer without delay.
7. International transfers
Whenever personal data are transferred outside the EEA, iBetterCoach ensures the application of Standard Contractual Clauses (SCC) approved by Commission Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures (enhanced encryption, pseudonymisation, contractual restrictions on access by public authorities), in compliance with the Schrems II ruling (C-311/18) and the current EU-US Data Privacy Framework.
8. Security and data breaches
8.1 Security measures
The applicable technical and organisational measures are described in Section 4 of this DPA.
8.2 Breach notification
In the event of a personal data breach, iBetterCoach:
- Notifies the Customer within 48 hours of becoming aware, with:
- Nature of the breach and categories of data involved
- Approximate number of Data Subjects and records affected
- Likely consequences
- Measures taken or proposed to mitigate
- Cooperates fully with the Customer for the notification to CNPD (within 72h) and, where applicable, to the Data Subjects.
9. Audits
The Customer has the right to audit iBetterCoach's compliance with this DPA, subject to:
- Written request 30 days in advance
- Maximum frequency of one audit per year (except in case of incident)
- Independent auditor bound by confidentiality
- Costs borne by the Customer, unless the audit reveals material non-compliance
iBetterCoach may alternatively provide third-party audit reports (e.g., SOC 2, ISO 27001, GDPR audit by an independent body) that satisfy the request.
10. Return and deletion of data
Upon termination of the contract, and at the Customer's option exercised within 30 days, iBetterCoach will:
- Return the personal data in structured format (JSON or CSV) via a secure mechanism, or
- Delete the personal data, except for what the law requires to be retained (see 10.1).
After 30 days without instructions from the Customer, iBetterCoach automatically deletes the data, unless legal retention obligations apply.
10.1 Retention by legal obligation
Deletion erases or anonymises the personal data and the health data, but retains what the law requires:
- Billing and accounting records: retained by tax/accounting obligation (~10 years in Portugal — ⚠️ exact period to be confirmed by the lawyer/accountant). These records are not deleted upon account deletion; only the user identifier is anonymised.
- Any clinical record that the health professional has a legal duty to retain — ⚠️ to be confirmed by the lawyer as to applicability, period and the role of each party in retention.
It is not accurate to state that "everything is deleted": the Platform ensures transparency at the moment of the action (in-app in the mobile application, public page and settings on the web), informing that "this deletes X; Y is retained for Z by legal obligation".
10.2 Deletion of the Athlete's account
The Athlete has direct mechanisms to request the deletion of their data — in the mobile application (in-app), through a public page and in the web settings — with the same logic of transparency at the moment of the action described in 10.1.
11. Liability
Each Party is liable for damages caused by breach of its obligations under Article 82 GDPR. iBetterCoach's liability towards the Customer is subject to the limitation of liability set out in the Terms of Use, except in cases of wilful misconduct or gross negligence.
12. Governing law and jurisdiction
This DPA is governed by Portuguese law. Any dispute shall be submitted to the courts of [to be defined], with express waiver of any other jurisdiction.
13. Acceptance
This DPA is deemed accepted by the Professional Customer upon account creation on the Platform and/or upon the first upload of Athlete personal data, without the need for a physical signature, in line with Article 28(9) GDPR which permits electronic form.
The Customer may request a bilaterally signed version at dpo@ibettercoach.com.
Document prepared for iBetterCoach. Requires formal legal review before publication.